settlement

HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000$90,000

Resolution Oct 2024

Penalty

$90,000

Action type

Settlement

Entity profile

Case number

What went wrong

HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000 - October 31, 2024

Timeline

  • ResolutionOct 2024
  • Incident and investigation milestones are not consistently published by OCR in machine-readable form.

Key takeaways for your organization

  • Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.
  • Run tabletop exercises for breach response, OCR inquiry handling, and privilege-preserving communications with counsel.
  • Revisit business associate inventory and downstream vendor security assurances after major enforcement themes in your sector.

Related actions

Source

U.S. Department of Health and Human Services release

Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use — not legal advice.